UK Housebuilder
The Client
One of the UK’s principal housebuilders, this FTSE 100 listed company employs around 5,000 people across numerous locations, supporting fifteen times as many jobs in the construction sector.
Teed worked with the client to review DR processes and BC preparedness in line with ISO/IEC 27031:2025 (Cybersecurity - Information and communication technology readiness for business continuity).
The standard describes relevant concepts and provides a framework of methods and processes to identify and specify aspects for improving an organisation's ICT readiness to ensure business continuity.
The Challenge
In the year prior to engaging Teed, our client worked hard to develop an IT disaster recovery (DR) plan and associated technical response procedures. The input focused on several elements designed to bring the business to a greater level of resilience.
Recognising they had gone as far as they could using internal resource, firstly the client needed an independent view to validate the DR and cybersecurity work. Having identified implementation actions, this was a good time to confirm they were on the right track.
The second element was to address the lack of maturity of business continuity (BC) in some areas. The business did not have a thorough appreciation of technology risk exposures, business priorities, and how to manage critical activities in contingency mode. An external specialist coming in and explaining what needed to happen to link DR and BC would enable a greater level of buy-in.
The third aspect was the changing IT environment as the business moves away from on premise solutions to cloud hosted and third-party managed SaaS solutions. It was recognised that this new approach has many benefits but introduces less control over certain aspects. Even when the responsibility for managing risks are transferred to third parties, these risks are still owned by the business and the consequences of threats being realised need to be carefully considered. The client needed support to identify how much they could practically do to help ensure a watertight response.
The Solution
1. Comprehensive DR review and exercise
The project kicked off with Teed’s consultant reviewing DR documents and undertaking discussions to understand the current set up, RTOs and RPOs, and IT assumptions on business priorities. This identified potential improvements to response/recovery documentation and the supporting capabilities, testing and assurance processes.
A tabletop DR exercise was held to challenge the review findings involving key representatives who would manage an incident and recover IT services. Three scenarios were considered: Cybersecurity incident at a third-party data centre; loss of core supplier services; network disruption.
The consultant’s findings were delivered as a combined DR review and exercise outcome report. Independent views on preparedness and areas for improvement were provided against 10 core elements aligning with ISO 27031 guidance, with each allocated an appropriate RAG score based on the current position. A clear roadmap of improvement activity was provided, further cybersecurity improvements and DR testing being clear priorities.
2. BC exercise
Identified in the previous DR review project as an action, the client engaged Teed subsequently to run a BC exercise to help achieve buy-in from the business. Managers being exposed to scenarios involving IT failures and cybersecurity issues where they are responsible for managing the business consequences does concentrate the mind.
The output highlighted further actions that need to be taken by the business to ensure effective incident management and business recovery, including the implementation of appropriate contingencies and workarounds for critical activities in the event of feasible technology disruptions.
3. Annual DR exercise
Teed was asked to undertake a further DR tabletop exercise, this time combined with the implementation of DR governance. The consultant produced a DR status report with a dashboard showing improvements on the previous year for delivery to the Risk & Audit committee, together with a plan of action for the coming year. The DR exercise and review is to be undertaken on an annual basis henceforth.
The Result
Teed’s input really helped the client to progress in a logical and pragmatic manner. Improvement actions from the exercises are being taken forward gradually. Significant progress has been made since the outset and although not finished yet, the client knows where they want to be and how to get there.
The focus on DR, BC and cybersecurity has resulted in executives having a greater degree of confidence that these are being managed effectively and has helped free up the necessary resource and budget to allow any gaps to be addressed.
Bringing in external expertise helped the client to assess the level of risk, identify the most effective controls and justify investment in maintaining a robust IT environment. Aligning to ISO 27031 provides assurance that best practice is being followed.